maciejrebisz.com

IT

Conditional Access for O365 based on location – Cloud First

maximios June 10, 2023

Like my previous blogpost on Conditional Access are this a setting not in Intune – but directly a AzureAD feature (Preview)

Now we just have to get around that Conditional Access is not only a question about compliance on the device – but the conditional can also be based on location.

This is pretty cool if you need to block all access to O365 based on location or just require MFA when your outside your company.

To configure this you need to go into the AzureAD portal https://portal.windowsazure.com

Go into your AzureAD directory -> Applications

Find the Office 365 application

Go into configure

Set the “Enable Access rules” to on

Apply it to all users or a specific group (I have a Except group also – so that it not conflict with my Conditional Access in my Intune)

Select “Block Access when not at work”

In the “Click here to define/edit your network location” you will be taken to your Azure MFA setting page

If you have not configured your “Skip multi-factor authentication…” then you have to put in your outside IP range for the company.

How does this look likes for a user perspective in a webbrowser when trying to access portal.office.com

Just login as normal – and you get access to your application list – start the mail.

Then you get blocked if your not accessing O365 from the IP scope you have defined in the MFA settings.

I you click “More details” you can see a list of information – and one of them is what IP address your come from.

Remember this is a feature in preview – but you can start testing 🙂

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ How to set UI language on Edge with Intune – Cloud First › OMS – Cloud First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes